An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload restrictions.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T11:06:09.511Z

Reserved: 2020-03-13T00:00:00

Link: CVE-2020-10557

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-16T15:15:12.583

Modified: 2024-11-21T04:55:34.527

Link: CVE-2020-10557

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.